NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1263 most downloaded on Packagist
SAML 2.0 PHP library
Last release 28 days ago
10 Sep 2026
Release timing varies
gaps range from 9 days to 12 months
Most releases are documented
notes for 46 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
74 releases · first in 2015
Adopt xmlseclibs 4.0 safe-by-default hardening: CVE-2025-23369 entity-reference signature bypass, SignatureMethod/key algorithm binding, RSA-1.5 (Blei…
Full Changelog: 5.1.0...6.0.0
One column per quarter.
Reject Responses with duplicate assertion IDs
Full Changelog: 5.0.1...5.1.0
LightSAML 5.0.0 was vulnerable to an XML Signature Wrapping (XSW) attack allowing an attacker who has captured one genuine signed assertion to have Li…
LightSAML 5.0.0 was vulnerable to an XML Signature Wrapping (XSW) attack
allowing an attacker who has captured one genuine signed assertion to have
LightSAML accept a fully attacker-authored assertion as IdP-signed, leading
to authentication bypass and privilege escalation.
The fix enforces two invariants before signature validation: the ds:Signature
parent element must carry the ID referenced by the fragment URI, and that ID
must be unique in the document.
Full Changelog: 5.0.0...5.0.1
Remove deprecated Serializable interface from state classes
Full Changelog: 4.7.0...5.0.0
LightSAML 4.x was vulnerable to an XML Signature Wrapping (XSW) attack ( GHSA-w553-pwx6-3mg9 / CVE-2026-63182) allowing an attacker who has captured o…
Backport to the 4.x line of the fix released in 5.0.1 (#113), for consumers
pinned to litesaml/lightsaml: ^4.0 that cannot adopt the 5.0.0 breaking
changes.
LightSAML 4.x was vulnerable to an XML Signature Wrapping (XSW) attack
(GHSA-w553-pwx6-3mg9 / CVE-2026-63182) allowing an attacker who has captured
one genuine signed assertion to have LightSAML accept a fully attacker-authored
assertion as IdP-signed, leading to authentication bypass and privilege
escalation.
The fix enforces two invariants before signature validation: the ds:Signature
parent element must carry the ID referenced by the fragment URI, and that ID
must be unique in the document.
Full Changelog: 4.7.0...4.7.1
Bump dependencies to address security vulnerabilities
Full Changelog: 4.6.1...4.7.0
Update robrichards/xmlseclibs to 3.1.4
Nothing published for this version
RoleDescriptor::getAllKeyDescriptorsByUse() dont fail on null keyDescriptors
### Styles * Use PHP CS Fixer as linter
Can handle compressed or uncompressed post request
Mark Pimple Bridge classes as deprecated
### Bug Fixes * Can use Symfony v7+
Use Schema::validate in XsdValidator
### Documentation * Change cookbook URL
Remove implicitly nullable parameter declarations
### Features * Supports Symfony 7.x
Always use random_bytes() in Helper::generateRandomBytes()
random_bytes() in Helper::generateRandomBytes()bin2hex() in Helper::stringToHex()### Bug Fixes * Php 8.1 deprecation notices
Prevent running test on changelog update
### Documentation * Update document URL * Clean changelog
Add deprecation to usage of Serializable interface
Compliant with Symfony 6 session recommendations
### Features * Allow Symfony 6 and Monolog 3
### Documentation * Change documentation URL
Add script in composer for test, phpcs & phpstan use in CI
Remove .changelog and README.md from export
Development files won’t be added to git archive
Move assets to .github directory
### Code Refactoring * Introduce PSR-4 autoloading
### Documentation * Add LICENSE document.
Automatic update of CHANGELOG on commit on master
Clean code by removing unnecessary backslash
Replace symfony/event-dispatcher dependency by psr/event-dispatcher
+ Change package description
Fix composer documentation settings
+ Fix Documentation
Move doc in dedicated repository
Fix LightSaml\Model\XmlDSig\SignatureXmlReader::validate() exception catching
Fix return types in LightSaml\Context\AbstractContext & LightSaml\Meta\ParameterBag
Fix param types in LightSaml\Model\Assertion\Conditions class
Fix input id in SamlPostResponse
+ Update to symfony packages 6.0
+ Run tests by GitHub's actions
+ Update PHPUnit 8.4+
+ Clean code with php-cs-fixer
+ PHP 7.2+ & Symfony 5
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →